Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2753▼ 55 respecto a la semana anterior
Críticas / altas1422▲ 195 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)106▼ 394 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.8)0.22%—Paloaltonetworks Cortex XDR Broker VMAI10/9/202611/9/2026
A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged user with man-in-the-middle (MitM) access to execute code with root privileges on the Broker VM.
AplazadaAlta (7.1)0.16%—Neuro-cortex-memory Cortex MCP ServerAI14/8/202618/9/2026
The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` environment variable — automatically set by Claude Code to the currently open project directory — as a trusted Cortex developer checkout. When the `open_visualization` tool is…
En análisisBaja (1.1)0.14%—Paloaltonetworks Cortex XDR Broker VM9/7/202616/7/2026
A privilege escalation vulnerability in Palo Alto Networks Cortex® XDR Broker VM enables a locally authenticated user to perform actions as the root user.
En análisisAlta (8.1)0.29%—Paloaltonetworks Cortex Xsiam Commvaultsecurityiq MarketplacePaloaltonetworks Cortex Xsoar Commvaultsecurityiq Marketplace10/6/202623/7/2026
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resources.
AnalizadaMedia (4.8)0.20%—Paloaltonetworks Cortex Xsoar10/6/202623/7/2026
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipulate network response traffic via a man-in-the-middle (MITM) attack, to write arbitrary files to the host.
Pendiente de análisisCrítica (9.1)0.54%—ARM C1-ultraAIARM C1-premiumAIARM Neoverse V3AIARM Neoverse V3aeAI+179/6/20264/9/2026
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.
Pendiente de análisisAlta (8.3)0.48%—Snowflake Cortex Code CLIAI16/4/202617/6/2026
Improper validation of bash commands in Snowflake Cortex Code CLI versions prior to 1.0.25 allowed subsequent commands to execute outside the sandbox. An attacker could exploit this by embedding specially crafted commands in untrusted content, such as a malicious repository, causing the CLI agent to execute arbitrary…
En análisisAlta (7.2)0.23%—Paloaltonetworks Cortex XsiamPaloaltonetworks Cortex Xsoar13/4/20267/7/2026
An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during integration of Microsoft Teams that enables an unauthenticated user to access and modify protected resources.
AnalizadaMedia (4)0.15%—Paloaltonetworks Cortex XDR Agent13/4/20267/7/2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows allows a local Windows administrator to disable the agent. This issue may be leveraged by malware to perform malicious activity without detection.
Pendiente de análisisMedia (5.7)0.17%—Paloaltonetworks Cortex XDRAI11/3/202617/6/2026
An information disclosure vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to obtain and modify sensitive information by triggering live terminal session via Cortex UI and modifying any configuration setting. The attacker must have network access to the Broker VM to exploit this…
Pendiente de análisisMedia (4)0.14%—Paloaltonetworks Cortex XDRAI11/3/202617/6/2026
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.
AplazadaAlta (8.1)0.50%—Mikado-themes CortexAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Cortex cortex allows PHP Local File Inclusion.This issue affects Cortex: from n/a through <= 1.9.
AnalizadaAlta (7.9)0.17%—ARM C1-ultra FirmwareARM C1-premium FirmwareARM Cortex-a710 FirmwareARM Cortex-x2 Firmware+714/1/202617/6/2026
In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another PE in the shareability domain. In this case, the PE may retain stale TLB entries which should have been invalidated by the TLBI.
AplazadaBaja (1)0.12%—Xilinx Versal Adaptive SOCAIARM Trusted Firmware FOR Cortex AAIARM Power State Coordination InterfaceAI23/11/202517/6/2026
The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State Coordination Interface (PSCI) commands were incorrectly set to secure instead of using the processor’s actual security state. This would allow the PSCI requests to appear they were from processors in…
AplazadaBaja (2.4)0.14%—Microsoft 365 DefenderAIPaloaltonetworks Cortex XDRAI12/9/202517/6/2026
A problem with the Palo Alto Networks Cortex XDR Microsoft 365 Defender Pack can result in exposure of user credentials in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these credentials are…
AplazadaMedia (5.3)0.17%—Paloaltonetworks Cortex XDR Broker VMAI13/8/202517/6/2026
A credential management flaw in Palo Alto Networks Cortex XDR® Broker VM causes different Broker VM images to share identical default credentials for internal services. Users knowing these default credentials could access internal services on other Broker VM installations. The attacker must have network access to the…
AplazadaMedia (4.6)0.19%—Paloaltonetworks Cortex XDR BrokerAI13/6/202517/6/2026
An incorrect privilege assignment vulnerability in Palo Alto Networks Cortex® XDR Broker VM allows an authenticated administrative user to execute certain files available within the Broker VM and escalate their privileges to root.
AplazadaMedia (6.5)0.49%—Paloaltonetworks Cortex XDR Broker VMAI14/5/202517/6/2026
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary code with root privileges on the host operating system running Broker VM.
AplazadaMedia (6.9)0.44%—Paloaltonetworks Cortex XDR Broker VMAI14/5/202517/6/2026
A missing authentication vulnerability in Palo Alto Networks Cortex XDR® Broker VM allows an unauthenticated user to disable certain internal services on the Broker VM. The attacker must have network access to the Broker VM to exploit this issue.
AplazadaMedia (6.3)0.56%—Paloaltonetworks Cortex XDR Broker VMAI11/4/202517/6/2026
A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execute arbitrary OS commands with root privileges on the host operating system running Broker VM.
AplazadaMedia (6.8)0.17%—Paloaltonetworks Cortex XDRAI11/4/202517/6/2026
A null pointer dereference vulnerability in the Palo Alto Networks Cortex® XDR agent on Windows devices allows a low-privileged local Windows user to crash the agent. Additionally, malware can use this vulnerability to perform malicious activity without Cortex XDR being able to detect it.
AplazadaMedia (6.8)0.20%—Paloaltonetworks Cortex XDRAI20/2/202517/6/2026
A problem with a detection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices enables a user with Windows non-administrative privileges to disable the agent. This vulnerability can also be leveraged by malware to disable the Cortex XDR agent and then perform malicious activity.
AplazadaMedia (5.3)0.26%—Paloaltonetworks Cortex XDR Broker VMAI12/2/202517/6/2026
A problem with the network isolation mechanism of the Palo Alto Networks Cortex XDR Broker VM allows attackers unauthorized access to Docker containers from the host network used by Broker VM. This may allow access to read files sent for analysis and logs transmitted by the Cortex XDR Agent to the Cortex XDR server.
AnalizadaMedia (5.1)0.20%—ARM C1-premium FirmwareARM C1-pro FirmwareARM C1-ultra FirmwareARM Cortex-x3 Firmware+528/1/202517/6/2026
An unprivileged context can trigger a data memory-dependent prefetch engine to fetch the contents of a privileged location and consume those contents as an address that is also dereferenced.
AnalizadaMedia (5.1)0.17%—ARM Cortex-a57 FirmwareARM Cortex-a72 FirmwareARM Cortex-a73 FirmwareARM Cortex-a75 Firmware22/1/202517/6/2026
In certain circumstances, an issue in Arm Cortex-A57, Cortex-A72 (revisions before r1p0), Cortex-A73 and Cortex-A75 may allow an adversary to gain a weak form of control over the victim's branch history.